Common Information
Type Value
Value
Scripting - T1064
Category Attack-Pattern
Type Mitre-Enterprise-Attack-Attack-Pattern
Misp Type Cluster
Description Adversaries may use scripts to aid in operations and perform multiple actions that would otherwise be manual. Scripting is useful for speeding up operational tasks and reducing the time required to gain access to critical resources. Some scripting languages may be used to bypass process monitoring mechanisms by directly interacting with the operating system at an API level instead of calling other programs. Common scripting languages for Windows include VBScript and PowerShell but could also be in the form of command-line batch scripts. Scripts can be embedded inside Office documents as macros that can be set to execute when files used in Spearphishing Attachment and other types of spearphishing are opened. Malicious embedded macros are an alternative means of execution than software exploitation through Exploitation for Client Execution, where adversaries will rely on macos being allowed or that the user will accept to activate them. Many popular offensive frameworks exist which use forms of scripting for security testers and adversaries alike. (Citation: Metasploit) (Citation: Metasploit), (Citation: Veil) (Citation: Veil), and PowerSploit (Citation: Powersploit) are three examples that are popular among penetration testers for exploit and post-compromise operations and include many features for evading defenses. Some adversaries are known to use PowerShell. (Citation: Alperovitch 2014) Detection: Scripting may be common on admin, developer, or power user systems, depending on job function. If scripting is restricted for normal users, then any attempts to enable scripts running on a system would be considered suspicious. If scripts are not commonly used on a system, but enabled, scripts running out of cycle from patching or other administrator functions are suspicious. Scripts should be captured from the file system when possible to determine their actions and intent. Scripts are likely to perform actions with various effects on a system that may generate events, depending on the types of monitoring used. Monitor processes and command-line arguments for script execution and subsequent behavior. Actions may be related to network and system information Discovery, Collection, or other scriptable post-compromise behaviors and could be used as indicators of detection leading back to the source script. Analyze Office file attachments for potentially malicious macros. Execution of macros may create suspicious process trees depending on what the macro is designed to do. Office processes, such as word.exe, spawning instances of cmd.exe, script application like wscript.exe or powershell.exe, or other suspicious processes may indicate malicious activity. (Citation: Uperesia Malicious Office Documents) Platforms: Linux, macOS, Windows Data Sources: Process monitoring, File monitoring, Process command-line parameters Defense Bypassed: Process whitelisting, Data Execution Prevention, Exploit Prevention Permissions Required: User
Details Published Attributes CTI Title
Details Website 2083-07-04 9 SonicWall VPN Portal Critical Flaw (CVE-2020-5135)
Details Website 2024-11-17 0 How Organizations Are Fulfilling CISA’s Secure by Design Pledge
Details Website 2024-11-17 0 Business Logic Assessments: Testing Overview
Details Website 2024-11-17 2 Malware and Cache
Details Website 2024-11-17 1 Automated Penetration Testing with Metasploit Framework
Details Website 2024-11-17 0 Getting Started with Cybersecurity.
Details Website 2024-11-17 0 Is Your API a Backdoor for Hackers? Find Out Now
Details Website 2024-11-17 0 SQL Injection vs. Cross-Site Scripting (XSS): Know the Difference!
Details Website 2024-11-16 2 Guide to Becoming an Ethical Hacker: From Basics to Advanced Knowledge
Details Website 2024-11-16 14 Building an Integrated Threat Intelligence Platform Using Python and Kibana
Details Website 2024-11-16 10 How Did I Get My First Collaboration Bounty Of $1000?
Details Website 2024-11-16 0 "We're stopping zero days before they're even used" — Security pros tell us how they are infiltrating cybercriminal networks and striking back from within | #cybercrime | #infosec | National Cyber Security Consulting
Details Website 2024-11-16 0 Top Strategies for Securing Application Layer Data
Details Website 2024-11-16 1 The Ultimate Cybersecurity Study Guide: Your Roadmap to Mastery
Details Website 2024-11-16 0 Web Security Automation: Your Shield Against Cyber Threats
Details Website 2024-11-15 0 BalckArch Linux Tools
Details Website 2024-11-15 7 Enhancing Wazuh Efficiency with AI: Meet the New AI Analyst in SOCFortress CoPilot
Details Website 2024-11-15 0 upgrading simple shells to fully interactive ttys
Details Website 2024-11-15 4 New Remcos RAT Activity Detection: Phishing Campaign Spreading a Novel Fileless Malware Variant - SOC Prime
Details Website 2024-11-15 1 OWASP Top 10 for LLMs: Protecting GenAI with AiFort
Details Website 2024-11-15 81 eJPT v2 Cert : Overview & Practice Labs
Details Website 2024-11-15 33 DONOT's Attack On Maritime & Defense Manufacturing
Details Website 2024-11-15 0 Enhancing security posture through advanced offensive security testing - Cybersecurity Insiders
Details Website 2024-11-14 1 Wordfence Intelligence Weekly WordPress Vulnerability Report (November 4, 2024 to November 10, 2024)
Details Website 2024-11-14 1 Cybersecurity 101: Specializations & Job roles — Part I